• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to secondary sidebar

Alston & Bird Privacy, Cyber & Data Strategy Blog

  • Home
  • Services
  • Events
  • Contacts

Kate Hanniford

NYDFS Issues Guidance on Artificial Intelligence-related Cybersecurity Risks

October 17, 2024 By Kim Peretti, Kate Hanniford, Ashley Miller, Lance Taubin and Colton Jackson

On October 16, 2024, the New York Department of Financial Services (“NYDFS”) issued an industry letter covering Cybersecurity Risks Arising from Artificial Intelligence and Strategies to Combat Related Risks (the “Industry Letter”).  The Industry Letter contains guidance for entities regulated by NYDFS (“Covered Entities”) in assessing and responding to cybersecurity risks related to the use […]

Filed Under: AI Cybersecurity & Privacy, Artificial Intelligence (AI), Board Governance & Cyber Risk Management, Privacy & Cyber Regulatory Enforcement

NYDFS Releases Industry Letter on the Use of Self-Service Password Reset Feature

January 23, 2024 By Kim Peretti, Kate Hanniford, Lance Taubin, Ashley Miller and Colton Jackson

On January 12, 2024, the New York State Department of Financial Services (“NYDFS”) released a new Industry Letter on the use of self-service password reset (“SSPR”) services, which enable users to reset their own password without the assistance of help desk or IT professionals. The Industry Letter discusses the risks associated with the use of […]

Filed Under: Board Governance & Cyber Risk Management, National Security & Digital Crimes Tagged With: Cybersecurity, SSPR

NYDFS Releases Consent Order in First Enforcement Action Brought Under the Cybersecurity Regulations

December 18, 2023 By Kate Hanniford, Lance Taubin, Ashley Miller and Kristen Bartolotta

After a three-year investigation/enforcement action by the New York Department of Financial Services (“NYDFS”), NYDFS entered into a Consent Order with a large title insurer (the “Company”) for its violation of NYDFS’s Cybersecurity Regulation (23 NYCRR Part 500) (the “Regulation”), specifically, its failure to protect non-public information (“NPI”). NYDFS originally brought the enforcement action in […]

Filed Under: Board Governance & Cyber Risk Management, Crisis & Data Breach Response, Privacy & Cyber Regulatory Enforcement Tagged With: Cybersecurity, Regulatory Enforcement, US State Law

Ransomware Group, in Midst of Extortion Attempt, Files Regulatory Notice with SEC

November 17, 2023 By Kim Peretti, Kate Hanniford, Alysa Austin and Lance Taubin

Just a month before the Security and Exchange Commission’s (“SEC’s”) Material Cybersecurity Incidents Rule is set to take effect, a ransomware group has apparently taken compliance with reporting requirements into its own hands.  On November 15, 2023, the ransomware group known as BlackCat (also known as “AlphV”) posted a notice on its leak site alleging […]

Filed Under: Board Governance & Cyber Risk Management, Crisis & Data Breach Response, National Security & Digital Crimes, Privacy & Cyber Regulatory Enforcement, Ransomware Fusion Center

FTC Approves New Data Breach Notification Requirement for Non-Banking Financial Institutions

October 31, 2023 By Kim Peretti, Kate Hanniford, Kathleen Benway and Lance Taubin

  On October 27, 2023, the FTC approved an amendment to the Safeguards Rule (the “Amendment”) requiring that non-banking financial institutions notify the FTC in the event of a defined “Notification Event” where customer information of 500 or more individuals was subject to unauthorized acquisition.  The Amendment becomes effective 180 days after publication in the […]

Filed Under: Board Governance & Cyber Risk Management, Consumer Protection/FTC, Crisis & Data Breach Response

  • « Go to Previous Page
  • Page 1
  • Page 2
  • Page 3
  • Page 4
  • Page 5
  • Interim pages omitted …
  • Page 11
  • Go to Next Page »

Primary Sidebar

This blog is a service of Alston & Bird’s Privacy, Cyber & Data Strategy team and focuses on key data privacy and data security issues.


Receive email notifications when new posts are added.

Receive email notifications when new posts are added.


RANSOMWARE FUSION CENTER
Click here to request access

THE DIGITAL DOWNLOAD
Click here to see the editions

PRIVACY & CYBER EVENTS
Click here to see upcoming and past events

PRIVACY & CYBER MAILINGS
Click here to sign up


Secondary Sidebar

Categories

Recent Posts

  • California AG Announces $1.4 Million Settlement with Mobile App Provider for Alleged CCPA Violations
  • SEC Dismisses Remaining Claims Against SolarWinds
  • The EU Digital Omnibus: A European Data Law Shake-Up May Be Coming
  • UK Cybersecurity Legislation Soon to be Introduced
  • Closing the Privacy Gap: HIPRA Targets Health Apps and Wearables
Copyright © 2025 · Alston & Bird · All Rights Reserved. Privacy.
This website uses cookies to improve functionality and performance. By continuing to browse this site, you are consenting to the use of cookies on this website.